TruStage

TruStage’s July 11 cyberattack affected its primary technology environment and backup infrastructure, forcing a cloud rebuild. As of Sept. 21, claims, policy servicing and disbursement functions remained partially available while restoration continued. TruStage also said it was developing grants for members who experienced incident-related hardship; data access, ransomware and attribution remained unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malicious software other than ransomware used to compromise or disrupt systems.
Malicious or negligent actions by an authorized insider resulting in cyber impact.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.
A primary service, system, platform, or operational capability became entirely unavailable.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
A specific application or software platform became unavailable or unusable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that malicious cyber activity affected TruStage’s technology environment and caused a prolonged systems outage. TruStage’s outage hub describes a broad cybersecurity attack identified July 11 and says the company had to rebuild parts of its infrastructure before safely returning systems to service. July 11 is the earliest supported detection date, not a confirmed intrusion-start date.
TruStage’s credit-union guidance says the investigation indicated that a workforce member may have inadvertently downloaded a malicious file while attempting to install a legitimate tool. DysruptionHub assesses malware and negligent insider action as probable mechanisms with medium confidence. TruStage has not identified the file, delivery route, malware family, affected hosts or subsequent attacker activity.
The incident disrupted customer and partner-facing insurance, claims, payment, transaction and account-access functions. TruStage used temporary processes for guaranteed asset protection claims, debt-protection benefits and mechanical-repair coverage, while credit unions were told to retain some monthly files until receipt and processing capabilities returned. The company acknowledged delays, processing exceptions and a claims backlog as systems came back online.
First Alert 4 reported that a delayed life-insurance payment postponed a Collinsville, Illinois, family’s funeral after Mary Farmer died Aug. 8. Her brother advanced the funeral cost before TruStage told the station Aug. 26 that it had resolved the claim. Missouri funeral directors also reported other funeral homes serving families while TruStage payments were pending. One other funeral-home delay began before the attack, so the incident does not explain its entire duration.
CU Today reported Sept. 11 that TruStage was developing a grant fund for credit union members who experienced incident-related financial hardship. CEO Terrance Williams acknowledged continuing service failures and said the investigation into possible member-data compromise would take at least two more months. The grant announcement documents continuing consequences but does not establish data compromise.
An Aug. 27 partner update reported by CU Today said the attack affected TruStage’s primary operating environment and elements of the backup infrastructure it expected to use for recovery. TruStage developed an alternate strategy that required rebuilding and restoring significant portions of its technology environment in the cloud. This establishes that backup systems were compromised as a recovery resource, but it does not establish that backup data was encrypted, deleted or permanently lost.
TruStage also canceled Discovery 2026, its virtual credit-union conference scheduled for Aug. 27, to focus on recovery and support for customers, partners and employees.
The incident remained active Sept. 21. TruStage’s official outage hub said some services remained unavailable and continued to list claims, policy servicing and disbursements as partially available while recovery proceeded. The company had not announced full restoration.
TruStage directly confirmed the cyberattack, network shutdown, infrastructure rebuilding and phased recovery. Its statements support containment and continuing restoration, but the public record does not explain precisely how the attack affected the backup environment or why the available backup layers could not support the planned recovery path.
The company said its investigation into whether member, employee or other information was compromised remained underway and could take another two to three months. The reviewed evidence does not establish encryption, a ransom demand, extortion, data publication or a responsible actor.
Cyber and operational-impact confidence are high because TruStage directly confirmed the attack and continued to document service effects. The CEO’s statement supports high confidence that elements of backup infrastructure were affected and that the recovery plan shifted to a substantial cloud rebuild. Confidence in malware and negligent insider action remains medium because the malicious-file finding is preliminary.
Availability impact is established for production services, data access and backup systems. Confidentiality and integrity effects remain unresolved because TruStage has not determined publicly whether information was accessed, acquired, altered or removed. Ransomware, extortion and threat-actor attribution also remain unresolved.
The public record does not establish the intrusion start, dwell time, delivery method, file or legitimate tool involved, malware family, affected hosts, persistence, lateral movement, privilege escalation or command-and-control activity. It does not identify which backup systems were affected, whether backup copies remained intact, how much recovery data was unavailable or how the attacker reached the backup environment.
The total number of affected customers, policies, claims, transactions, credit unions, funeral homes or other partners remains unknown. The final restoration date, size and disposition of deferred work, data-access findings and any notification obligations also remain unresolved.

We reported that TruStage shut down its network after identifying a cybersecurity incident and that some credit-union-linked claims were affected. TruStage had not disclosed the compromise method, data impact, restoration date, ransomware, a ransom demand or a threat actor.
CU Today reproduced TruStage’s stakeholder message stating that the company identified a cybersecurity incident, proactively shut down its network, activated incident-response and recovery efforts, and engaged external specialists for containment, remediation, and recovery.
Credit Union Times reported that TruStage President and CEO Terrance Williams told credit-union customers the investigation indicated a workforce member may have inadvertently downloaded a malicious file while attempting to install a legitimate tool. The report characterized this as the first public indication of how the incident may have begun.
Service 1st said TruStage identified the incident July 11, proactively shut down access to its network and systems, and was working to restore normal operations. Service 1st said its own systems were unaffected and it had not been informed that member information was compromised.
TruStage’s July 24 consumer update said investigation remained active and customers could have difficulty accessing account information, completing transactions or submitting requests online. Active coverage and grace-period policies would retain their status until regular payment processing resumed, and claims would be processed and paid once systems were able.
TruStage’s July 31 guidance said restoration remained underway; customers and representatives still faced account-access, transaction, request and payment limitations; claims would be paid as systems permitted; retirement balances were unaffected but online access was still being restored; and any personal-information access remained undetermined.
On Aug. 30, TruStage still listed claims submission, processing and payout; policy and contract servicing; and disbursements as partially available overall. BenefitsForYou remained unavailable, account access was limited, and multiple claims, payment and partner processes still depended on temporary channels.
TruStage said it had established a clean, isolated environment for phased restoration. Some contact centers, claims payments, billing and retirement withdrawals or loans had resumed, but longer handling times, limited capabilities and a claims backlog remained. The company said its data investigation could take another two to three months.
First Alert 4 reported that a delayed TruStage life-insurance payment postponed a Collinsville family’s funeral after an Aug. 8 death. TruStage said it resolved that claim and another claim described by the station after the inquiry. Missouri funeral directors also reported other funeral homes serving families while TruStage payments were pending. One woman’s reported stay at a funeral home began in June, before the July 11 attack, so the incident does not explain that entire delay.
CU Today reported that TruStage President and CEO Terrance Williams said the attack affected the company’s primary operating environment and elements of backup infrastructure intended for recovery. TruStage developed an alternate recovery strategy and rebuilt significant portions of its technology environment in the cloud. The company also named Kirsten Garen interim CIO, retained Pat Lawicki as a consultant and added PwC to the recovery effort. The report does not say backup data was encrypted, deleted or permanently lost.
CU Today reported that TruStage was developing a grant fund for credit union members who experienced incident-related financial hardship and that its investigation into possible member-data compromise would take at least two more months.
The credit union said vendor partner TruStage was experiencing systems outages and warned members of temporary inconvenience when submitting claims for GAP insurance, mechanical repair coverage, or payment protection products.
TruStage’s homepage still displayed a systems-down notice August 10 and described the event as a cybersecurity attack while teams worked on recovery and business-resiliency plans.
TruStage canceled Discovery 2026 because of the cybersecurity attack affecting certain systems and services. The company said the decision allowed it to focus on recovery and supporting customers, partners and employees, and that conference content would be moved to a later thought-leadership series.
On Aug. 30, TruStage’s dashboard showed annuity claim payouts unavailable and most other claim categories partially available. It expected most pre-outage life and accidental-death claims to be paid by the end of the following week, with some claims still needing documentation, and said review of guaranteed asset protection claims submitted after July 11 had begun.
On Aug. 30, TruStage listed life-policy one-time disbursements and surrenders as unavailable, retirement and executive-benefit disbursements as partially available, and annuity disbursements as available. The product-level variation showed significant recovery but not full restoration.
On Aug. 30, TruStage listed all Payment Guard servicing as unavailable, Bond Suite servicing as largely unavailable, and life, accidental-death, retirement and several other product functions as partially available. Annuity and third-party-supported products had broader restoration, but the dashboard did not show complete servicing recovery across the business.
TruStage’s Sept. 21 outage hub said restoration continued after the July 11 attack. Claims, policy servicing and disbursement functions remained partially available, and some services remained unavailable.
Signed-in members can report an error, update, or missing source.